Conversation

Even an industrial tooling company in Estonia managed to find the secret DNSSEC-signed Google MX hosts. Official support and TLSA RRs would sure be nice: venten․ee․ MX 10 mx1․smtp․goog․ @ MX 20 mx2․smtp․goog․ @ MX 30 mx3․smtp․goog․ @ MX 40 mx4․smtp․goog․
1
5
Thing is, that in this case a "2 1 1" record that specifies the current Google issuer CA does not require "keeping certs in sync". This is true even when the CA rolls over, since *multiple* TLSA RRs can cover the current and next CA during the rollover. The certs roll normally.
2
2